AI Governance Library

European Union Artificial Intelligence Act: a guide

A law firm guide to the EU Artificial Intelligence Act, published by Bird & Bird and dated 6 November 2024, working through scope, prohibited practices, high-risk systems, general-purpose AI models, transparency, sandboxes, enforcement and upcoming secondary legislation.
Cover of European Union Artificial Intelligence Act: a guide

⚡ Quick Summary

Published by Bird & Bird, this guide to the European Union Artificial Intelligence Act is dated 6 November 2024 and works through Regulation (EU) 2024/1689 chapter by chapter. Each of its ten chapters opens with an “At a glance” box and closes with a “To do list”, and the guide frames the Act as a risk-based, technology-neutral framework that sorts AI systems into unacceptable, high, limited and minimal risk.

The guide covers material and territorial scope and the six operator roles; the eight prohibited practices in article 5; high-risk classification under article 6 and Annexes I and III, the article 6(3) exemptions, provider and deployer duties, harmonised standards and conformity assessment; obligations for general-purpose AI models, including the 10^25 floating-point operations presumption for systemic risk; article 50 transparency; regulatory sandboxes and real-world testing; and enforcement, governance and tiered fines of up to €35 million or 7% of worldwide turnover.

It closes with application dates running from 12 July 2024 to 31 December 2030 and with the delegated acts, implementing acts, guidelines, codes of practice, standards and the revised AI Liability Directive proposal expected to follow.

🧩 What’s Covered

The guide runs to ten chapters, each with an “At a glance” summary and a “To do list”.

  • Overview, key concepts and timing (Chapter 1): the risk-based, technology-neutral approach, the article 3(1) definition of an AI system and its “infer” test, the four risk levels, supply-chain roles, the AI Office and European AI Board, and a table of application dates from 12 July 2024 to 31 December 2030.
  • Material and territorial scope (Chapter 2): the six operator categories, the terms “making available”, “placing on the market” and “putting into service”, the article 86 right to explanation, exclusions (military, defence, national security, research, personal use, open source) and the relationship with the GDPR and EU product legislation.
  • Prohibited AI practices (Chapter 3): the eight article 5 prohibitions, from subliminal techniques to real-time remote biometric identification, their exceptions and recitals, and fines of up to €35 million or 7% of worldwide turnover.
  • High-risk AI systems (Chapter 4): classification under article 6 via Annexes I and III, the article 6(3) exemptions, provider duties under articles 8–15, conformity assessment, CE marking, EU database registration, deployer obligations including the fundamental rights impact assessment, and duties of importers, distributors and suppliers.
  • General-purpose AI models (Chapter 5): the model/system distinction, recital 98 indicators, article 53 provider obligations (technical documentation, copyright policy, training-data summary, authorised representative) and the systemic-risk regime.
  • Transparency obligations (Chapter 6): article 50 duties for chatbots, synthetic-content marking, emotion recognition and biometric categorisation, and deepfakes; marking methods such as watermarks, metadata and cryptographic signatures; exemptions; and links to the DSA and GDPR.
  • AI regulatory sandboxes (Chapter 7): the sandbox definition, one sandbox per Member State by 2 August 2026, SME and start-up incentives, personal-data conditions, real-world testing (six months maximum, informed consent) and forum-shopping risk.
  • Enforcement, governance and next steps (Chapters 8 and 9): post-market monitoring and serious-incident reporting timelines, market surveillance powers including access to source code, the tiered penalty table, remedies for third parties, the EU and national bodies, and the delegated acts, guidelines, codes of practice and CEN-CENELEC standards expected through 2028.

💡 Why it matters?

For organisations caught by the AI Act, the guide turns a long regulation into an operational map: which role in the value chain triggers which duties, which systems are prohibited from 2 February 2025, and what providers must document, test and register before placing a high-risk system on the EU market. It is explicit about the interaction with adjacent regimes — the GDPR, the Digital Services Act, the Cyber Resilience Act, the Medical Device Regulation and Union harmonisation legislation generally — and about the secondary instruments, such as harmonised standards, common specifications and codes of practice, on which practical compliance will depend.

❓ What’s Missing

The guide is a law-firm commentary rather than an assessment tool: beyond the chapter “To do list” boxes it offers no templates, checklists or scoring for conformity work, and no worked examples of the technical documentation, quality management system or fundamental rights impact assessment. The article 6(5) classification guidelines and the harmonised standards the text relies on were still outstanding when it was written, so several duties are described at the level of the Regulation. Coverage of national implementation, sector-specific rules, and the copyright and data-protection questions around training data remains brief.

👥 Best For

Compliance, legal and governance teams mapping the AI Act’s obligations to their own role in the value chain, and product or engineering leads who need to know whether a system is prohibited, high-risk or subject to transparency duties before it reaches the EU market.

📄 Source Details

European Union Artificial Intelligence Act: a guide, published by Bird & Bird, dated 6 November 2024 on the cover. The PDF runs to 75 pages in English across ten chapters and includes a “Where can I find this?” table mapping topics to articles and recitals, a list of 33 contributors and a closing disclaimer. No document URL is printed; the only address given is the firm’s site, twobirds.com. The input was a full text extraction of all 75 pages.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.